In the past month, JPMorgan Chase, BB&T, American Express, TD Bank, and Wells Fargo suffered DDoS(distributed denial of service) attacks on their online banking portals. The attacks affected service only intermittently for a few hours, but signs are pointing to increased strength in attacks and that consumer banking sites may no longer be the primary target for DDoS attacks moving forward.
Last year, “hacktivists” by the name of al-Qassam Cyber Fighters launched attacks on all leading United States financial institutions in response to YouTube’s decision not to remove a religiously offensive film. Using between 2,000 and 3,000 “zombie” computers, the al-Qassam group, among others, were able to bringdown bank sites with unprecedented web traffic. In the months since, financial institutions have made great strides to level the playing field. Dave Ostertag, a global investigation manager with Verizon told the American Banker that, “Twelve months ago, the maximum protection for a major financial institution was 10 gigabytes per second, now we’re averaging 40 to 50 gigabytes per second. The entire industry has changed.”
Although financial institutions have improved their defenses, attacks have since grown in strength and are evolving to cause nightmares for those trying to mitigate the damage. Banks, however, may not be the primary target for DDoS attacks much longer as others in the payments industry are beginning to suffer as well.
In recent weeks, Bitcoin has dominated headlines as the currency reached new highs. But on April 3rd, the value of an individual Bitcoin fell $20 dollars due to outages at the world’s largest Bitcoin exchange, Mt. Gox. While speculation was abound about what led to the outages, the company’s Twitter account confirmed the site came under a DDoS attack. Bitcoin traders, however, were not the only payment firms affected by DDoS attacks recently. Payment start-up Dwolla and its third party developers also sustained a DDoS attack in early April, which brought down the site for a short time.
While the latest DDoS attacks have shown little in the way of more sinister intentions (like stealing card information or other sensitive information), the threat for such actions is ever present. At RSA Europe 2012, Francis de Souza, Symantec’s head of Enterprise Products and Services, underscored this sentiment by saying, “DDoSes have gone from being a blunt-forced attack to being a sophisticated diversionary attack to disguise another attack. “Though customer service problems may be the most pressing issue with DDoS attacks today, it may be only a matter of time before one results in something more serious.
For more in-depth coverage and insight into DDoS attacks and their payment fraud implications, see Mercator Advisory Group’s research note, “Distributed Denial of Service Attacks and Potential Fraud Implications.”
